Serious vulnerabilities in a Joomla plugin!

Kasper Bertelsen warns that several vulnerabilities he discovered in Joomla's Helpdesk Pro can lead to remote code execution on hosts hosting the Web application.joomla

Helpdesk Pro is an extension of Joomla that allows administrators and users to use support bids.

Let's mention some websites that use this : eBay, Heathrow Airport, and the High Court of Australia.

Vulnerabilities were discovered by Simon Rawet, Kristian Varnai, and Gregor Mynarsky, and include: direct object references, cross-site scripting, SQL injection, local file injection, arbitrary file upload.

“[Vulnerabilities] leave systems vulnerable to a wide variety of attack types, resulting in the disclosure of potentially sensitive information, but also in the complete acquisition of with arbitrary code execution," they report.

Vulnerabilities work because the συνημμένων και οι upload restrictions do not restrict someone from downloading files.

So an attacker can download the configuration.php file, for example, which contains sensitive information such as user names, database passwords, and FTP credentials.

More technical details.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).